Rop Chain Thought

In Defending Rop Chains, a method of stealing pagetable permissions (rwx?) within functions
is shown as a solution to sucessfully defend. But I read an earlier article, where 
Rop Gagdets are not dependent from the current function. Instead code is read here and
there.That way, instructions at current patched functions are ignored and can be found
elsewhere. Also, in a given test situation, one could re-add the pagetable permissions.

DuckAlert:

If, on a host, one cannot read certain pages, an analysis of 
- a similar binary or
- a download of the binary invoked through 3rd parties can
be a way of look at the err, rop chain. depends what perm is stolen. blah